Cleartext storage of sensitive information in Fujitsu products - CVE-2023-39903

 

Cleartext storage of sensitive information in Fujitsu products - CVE-2023-39903

Published: September 14, 2023


Vulnerability identifier: #VU80784
CSH Severity: Low
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N]
CVE-ID: CVE-2023-39903
CWE-ID: CWE-312
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to potentially sensitive information.

The vulnerability exists due to cleartext storage of sensitive information in the ismsnap component. A local user can retrieve the password for the proxy server that is configured in ISM.


Affected software

Infrastructure Manager Advanced Edition
Infrastructure Manager Advanced Edition for PRIMEFLEX
Infrastructure Manager Essential Edition

How to mitigate CVE-2023-39903

Install updates from vendor's website.

Infrastructure Manager Advanced Edition - update to 2.8.0.061
Infrastructure Manager Advanced Edition for PRIMEFLEX - update to 2.8.0.061
Infrastructure Manager Essential Edition - update to 2.8.0.061

External References

Related Security Bulletins